The tooling which enables ESLint to work with Angular projects
68%
Total Score
caution
Active, well-supported package, but workflow injection risks and entirely unpinned actions materially reduce supply-chain confidence.
All eight workflows were analyzed and use read-only permissions, with no untrusted checkouts or script-injection findings. However, all 42 action references are unpinned, and high-confidence template-injection findings occur in workflows using pull_request-related or workflow_run triggers; unsound conditions and adhoc package installs add caution.
The project uses established build tooling including TypeScript, Nx, esbuild, Vite, and SWC, but no security-scanning tools were detected; the latter is a modest hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
@angular-devkit/core Version >= 22.0.0 < 23.0.0 | — | — |
@angular-eslint/builder Version 22.6.0 | — | — |
@typescript-eslint/types Version ^8.0.0 | — | — |
@typescript-eslint/utils Version ^8.0.0 | — | — |
@angular-devkit/schematics Version >= 22.0.0 < 23.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.